5.3

CVE-2022-2795

Processing large delegations may severely degrade resolver performance

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Isc ≫ Bind SwEdition - Version >= 9.0.0 < 9.16.33
Isc ≫ Bind SwEdition - Version >= 9.18.0 < 9.18.7
Isc ≫ Bind SwEdition - Version >= 9.19.0 < 9.19.5
Isc ≫ Bind Version 9.9.3 Update s1
Isc ≫ Bind Version 9.9.3 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.9.12 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.9.13 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.10.5 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.10.7 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.3 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.5 Update s3
Isc ≫ Bind Version 9.11.5 Update s3 SwEdition supported_preview
Isc ≫ Bind Version 9.11.5 Update s5 SwEdition supported_preview
Isc ≫ Bind Version 9.11.5 Update s6 SwEdition supported_preview
Isc ≫ Bind Version 9.11.6 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.7 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.8 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.12 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.14-s1 SwEdition preview
Isc ≫ Bind Version 9.11.19-s1 SwEdition preview
Isc ≫ Bind Version 9.11.21 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.27 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.29 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.35 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.37 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.8 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.11 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.13 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.21 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.32 Update s1 SwEdition supported_preview
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Fedoraproject ≫ Fedora Version 35
Fedoraproject ≫ Fedora Version 36
Fedoraproject ≫ Fedora Version 37
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.72% 0.751
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
ISC 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://security.gentoo.org/glsa/202210-25
Third Party Advisory
http://www.openwall.com/lists/oss-security/2022/09/21/3
Patch
Third Party Advisory
Mailing List
https://kb.isc.org/docs/cve-2022-2795
Patch
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2022/10/msg00007.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2022/dsa-5235
Third Party Advisory
https://security.netapp.com/advisory/ntap-20241129-0002/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S/